CVE-2026-62139: WordPress Site Kit by Google plugin <= 1.186.0 - Cross Site Request Forgery (CSRF) vulnerability
Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Site Kit by Google pluginto a version that resolves this vulnerability.Fixed in 1.187.0
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
An attacker needs to cause a victim to interact with a crafted request, as indicated by the required user interaction in the CVSS vector. The attack can be delivered over the network and does not require the attacker to authenticate.
What is the likely impact if exploitation succeeds?
The reported impact is limited to integrity, with no reported confidentiality or availability impact. The CVSS vector rates integrity impact as low.
Which installations should be investigated?
Investigate sites using the Google Site Kit by Google WordPress plugin at version 1.186.0 or earlier. The provided data does not identify a configuration-based exception.